Description

An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling a remote attacker to inject formula data into a generated CSV file. The exploitation of this vulnerability requires the attacker to create a malicious link. The user would need to click on this link, after which the resulting CSV file addi-tionally needs to be manually opened.

INFO

Published Date :

2025-10-14T12:42:59.143Z

Last Modified :

2025-10-14T15:31:36.665Z

Source :

ABB
AFFECTED PRODUCTS

The following products are affected by CVE-2025-11498 vulnerability.

Vendors Products
Br-automation
  • Automation Runtime
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-11498.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact